CVE-2006-3854
CVE-2006-3854
Buffer overflow in IBM Informix Dynamic Server (IDS) 9.40.TC7, 9.40.TC8, 10.00.TC4, and 10.00.TC5, when running on Windows, allows remote attackers to execute arbitrary code via a long username, which causes an overflow in vsprintf when displaying in the resulting error message. NOTE: this issue is due to an incomplete fix for CVE-2006-3853.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://securityreason.com/securityalert/1409https://exchange.xforce.ibmcloud.com/vulnerabilities/28381http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdfhttp://www.securityfocus.com/archive/1/443133/100/0/threadedhttp://www.securityfocus.com/archive/1/443150/100/0/threaded